---
id: CVE-2026-89558
title: >-
  kernel: md/raid10: fix still_degraded being inverted in raid10_sync_request()
  (CVE-2026-89558)
summary: >-
  A flaw was found in the Linux kernel's md/raid10 (RAID10) driver. This
  vulnerability occurs when a RAID10 array is in a degraded state and a device
  is being recovered while another mirror is still missing. Due to an inverted
  boolean value,…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-480
vendor: Red Hat
product: Red Hat Enterprise Linux 9
affected:
  - enterprise_linux 10
  - enterprise_linux 6
  - enterprise_linux 9
  - openshift_container_platform 4
published: '2026-09-11'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T22:06:53+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89558.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89558.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89558'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532221'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89558'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89558'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89558.mbox
  - url: 'https://git.kernel.org/stable/c/00449d752bee9c8787f42ea1bf533a9fb17f9b6b'
  - url: 'https://git.kernel.org/stable/c/0efabe6229dc683dbf6eeebd0f9fddc7971ed420'
  - url: 'https://git.kernel.org/stable/c/47f1441b281decde6954a2fa82b4131637d685ac'
  - url: 'https://git.kernel.org/stable/c/9bb8da6ecb330a5b1ac9b96f1e55f134a7aef1d4'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
  - score-dispute
epss: 0.00626
epssPercentile: 0.48671
scores:
  vendor: 4.4
  cna: 9.8
ingestedAt: '2026-09-14T15:23:07.474Z'
---

## Overview

A flaw was found in the Linux kernel's md/raid10 (RAID10) driver. This vulnerability occurs when a RAID10 array is in a degraded state and a device is being recovered while another mirror is still missing. Due to an inverted boolean value, the system incorrectly clears necessary bitmap bits, causing subsequent recovery operations to skip regions with stale data. This can lead to silent data corruption on the re-added device, impacting data integrity.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89558.json)

**kernel: md/raid10: fix still_degraded being inverted in raid10_sync_request()** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.

Affected:

- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

No fix planned:

- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4

Not affected:

- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat OpenShift Container Platform 4

## Remediation

Out of support scope
